Re: Wappush Contains Username/Password

Stipe Tolj <[email protected]>
Newsgroups gmane.comp.mobile.kannel.devel
Organization tolj.org system architecture
Message-ID <[email protected]>
Mathieu Bruneau schrieb:
> Yes, that's exactly want I wanted, remove the credentials since this is related to kannel functioning only. Not to wappush/sms in any way.
> 
> Here's an example line from our bearerbox_access log:
> 2007-11-27 19:17:48 Sent SMS [SMSC:smc1] [SVC:ppg] [ACT:] [BINF:] [from:1234] [to:+56978555555] [flags:-1:1:-1:-1:0] [msg:73:cc061fae871880757365726e616d6550407373773072642621008db1c39302056a0045c60c0372616e646f6d2e75726c0085030011030007010354657374206d657373616765000101] [udh:7:0605040B8423F0]
> 
> NB: I altered this to remove "sensible" information. I hope the format is still correct
> 
> If we decode it contains:
> username and P@assword which correspond to the ppg-username and ppg-password used. Since this is completely independent from the operator side I think this shouldn't be transmitted.

can you show us the PAP and content blocks itself too? So I can review at which 
point the credentials ARE necessary and where they are "bogus" to be send?

Thanks,
Stipe

-------------------------------------------------------------------
Kölner Landstrasse 419
40589 Düsseldorf, NRW, Germany

tolj.org system architecture      Kannel Software Foundation (KSF)
http://www.tolj.org/              http://www.kannel.org/

mailto:st_{at}_tolj.org           mailto:stolj_{at}_kannel.org
-------------------------------------------------------------------
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.